What Your Nonprofit Website Should Say During a Crisis
Key takeaways
- A website crisis is fundamentally a governance problem, revealing whether the organisation has the authority structures and content control to respond under pressure.
- During a crisis the website becomes the single authoritative source that journalists, funders, board members, and beneficiaries all check, and silence on it is read as incompetence or evasion.
- In the first 24 hours, review every page touching the issue, remove or update anything now inaccurate, and publish a clear factual statement attributed to a named individual such as the Chair or Executive Director.
- A crisis statement should be prominent but not permanent: a homepage banner linking to a dated, timestamped statement page rather than a wholesale replacement of the homepage.
- Content should be updated rather than deleted; suspended staff profiles come down, but programme pages are redirected or amended so search traffic is not lost.
- The governance framework should define in advance who can authorise urgent website changes, how quickly, and the escalation path if the usual owner or the Executive Director is the subject of the crisis.
Summary
A website crisis for a nonprofit is not primarily a communications problem. It is a governance problem — one that reveals, under pressure, whether the organisation has the structures, the authority, and the content governance to respond effectively when something significant goes wrong. The Communications Director who discovers during a funding crisis, a safeguarding incident, or a media investigation that the website contains inaccurate information, lacks a clear statement of governance oversight, or cannot be updated quickly without a developer, faces a governance failure that predates the crisis itself.The most common nonprofit website crisis scenarios each have specific governance implications: a funding cut that requires rapid communication to beneficiaries and partners, a safeguarding incident that requires a clear statement of the organisation's response and governance oversight, a media investigation that requires the website to present accurate information about leadership and governance, and a public controversy that requires the organisation to communicate its position without inadvertently creating new liabilities.This post covers the governance framework for nonprofit website crisis communication: what to publish, what to remove, in what timeframe, with what governance oversight, and how to document the decisions in a way that protects the organisation. It covers the specific content categories that need governance review in each crisis scenario, the access credentials and publishing permissions that need to be in place before a crisis occurs, and the post-crisis review process that translates the crisis experience into improved governance infrastructure.
When a crisis hits — a funding cut, a safeguarding incident, a media investigation — the website becomes the organisation’s public record. What it says, what it does not say, and how quickly it changes all signal institutional competence to every stakeholder watching.
Most nonprofits do not have a plan for how the website should function during a crisis. The homepage still promotes a programme that has been defunded. The team page still lists a staff member who has been suspended. The annual report page links to accounts that are now under scrutiny. These are not communications oversights. They are governance failures that compound the crisis.
Why the Website Matters More During a Crisis
During normal operations, your website is one of many communications channels. During a crisis, it becomes the single authoritative source that every stakeholder consults. Journalists check it before calling your press office. Funders check it before deciding whether to continue their relationship. Board members check it before the emergency meeting. Beneficiaries check it for information about whether services are affected.
If the website contradicts what the organisation is saying in other channels, the website is what people believe. If the website says nothing while a crisis unfolds publicly, silence is interpreted as either incompetence or evasion. Neither interpretation serves the organisation.
The First 24 Hours
The website response in the first 24 hours of a crisis sets the tone for everything that follows.
Assess what the website currently says about the issue. Before publishing anything new, review every page that touches the crisis. If a programme has been defunded, check every page that references it. If a staff member is involved, check the team page, any authored content, and programme pages they are associated with. If a partner organisation is involved, check for logos, testimonials, and joint programme descriptions.
Remove or update content that is now inaccurate or harmful. This is not censorship. It is ensuring the website reflects the organisation’s current reality. A team page listing someone who has been suspended is not transparency — it is negligence. A programme page promoting an initiative that no longer exists is not historical record — it is misinformation.
Publish a clear, factual statement if the crisis is public. If the crisis is in the public domain — media coverage, social media, or stakeholder communications — the website should carry the organisation’s official position. This does not need to be lengthy. It needs to be clear, factual, and attributable to a named individual (usually the Chair or Executive Director).
The statement should cover: what the organisation is aware of, what action is being taken, who is leading the response, and how stakeholders can get further information. Avoid speculation, blame, or commitments the organisation cannot yet make.
What to Publish and Where
A crisis statement should be prominent but not permanent. Do not replace the homepage with a crisis message unless the crisis directly affects every visitor to the site. Instead, add a banner or notification that links to a dedicated statement page.
Crisis statement page. Create a standalone page (e.g. /statement or /update) with the official position. Date it. Update it as the situation evolves. Each update should be timestamped so stakeholders can see the progression of the response.
Homepage notification. A brief, factual banner linking to the statement page. This ensures every visitor is aware without replacing the site’s core content.
Governance section. If the crisis relates to governance, compliance, or regulatory matters, ensure the governance section of the site reflects current reality. If the Board has issued a formal response, it should be accessible from this section.
What to Remove or Update
Staff and leadership pages. If individuals are involved in the crisis, their profiles should be updated or removed in consultation with legal counsel and HR. Do not leave profiles of suspended or departed individuals visible during an active investigation.
Programme pages. If a programme has been defunded, suspended, or is under review, the page should be updated to reflect the current status. Do not delete the page entirely — it may still receive search traffic and should redirect or inform visitors of the current situation.
Partnership references. If a partner organisation is involved in the crisis, review all pages that reference the partnership. Logos, testimonials, and joint programme descriptions may need temporary removal pending resolution.
Impact data and claims. If the crisis involves questions about the organisation’s effectiveness, outcomes, or financial management, review all impact claims on the site. Anything that cannot be substantiated should be removed or caveated until it can be verified.
The Governance Framework for Crisis Response
Website crisis response should not depend on the Communications Director’s judgment alone. The governance framework should define:
Who can authorise website changes during a crisis. Normally, the Communications Director manages the site. During a crisis, changes to public-facing statements may require sign-off from the Chair, Executive Director, or legal counsel. Define this in advance.
How quickly changes must be made. The website should be updated within hours of a crisis becoming public, not days. If your CMS requires developer access for urgent changes, this is a governance risk that should be resolved before a crisis occurs.
What the escalation path is. If the Communications Director is unavailable, who can make website changes? If the Executive Director is the subject of the crisis, who authorises the response? These scenarios should be documented in your website governance policy.
After the Crisis
Once the immediate crisis has passed, the website needs a structured return to normal operations.
Archive the crisis statement page rather than deleting it. It is part of the institutional record and demonstrates the organisation’s response to future funders or regulators who may ask about it.
Review all content that was updated during the crisis. Were temporary changes made that need to be reversed? Were pages updated that now need more considered revisions?
Conduct a governance review of how the website response worked. Was the organisation able to update the site quickly enough? Were the right people able to authorise changes? Did the CMS structure support rapid response? Feed findings into the governance policy.
The Blueprint Audit includes an assessment of the site’s capacity for rapid content updates as part of the governance review. If your current platform or access structure would prevent timely crisis response, the audit identifies this as a specific risk.
For the governance policy framework that should include crisis provisions, see How to Create a Website Governance Policy. For the broader governance context, see Why Your NGO Website Is a Governance Problem.
Blueprint Audit
See what a funder sees.
The Blueprint Audit is a £2,500 governance diagnostic with a Board-ready roadmap. It stands alone, with no obligation to continue.
Frequently asked questions
A clear, factual statement covering: what the organisation is aware of, what action is being taken, who is leading the response, and how stakeholders can get further information. Avoid speculation, blame, or commitments that cannot yet be made. Date and timestamp all updates.
Within hours of a crisis becoming public. If your CMS requires developer access for urgent changes, this is a governance risk. The Communications Director should be able to publish a statement and update key pages without waiting for external support.
Consult legal counsel and HR before making changes. Generally, profiles of suspended individuals should be removed or updated. Profiles of departed individuals should be removed. Do not leave visible profiles that create a misleading impression of current leadership.
On a dedicated statement page linked from a homepage banner or notification. Do not replace the homepage entirely unless the crisis affects every visitor. The statement page should be dated, timestamped with each update, and attributable to a named individual.
Generally no. Update content to reflect current reality rather than deleting it. Deleted pages can still appear in search results and cached versions. If a programme has been suspended, update the page to reflect the status rather than removing it entirely.
Define this in your governance policy before a crisis occurs. Typically, public-facing statements require sign-off from the Chair or Executive Director. If the ED is the subject of the crisis, the Chair or a designated trustee should authorise website changes.
Ensure the website and media responses are consistent. Journalists will compare what the website says with what the press office says. Any contradiction undermines credibility. The website statement should be approved by the same person authorising media responses.
Archive rather than delete. Remove the homepage banner once the immediate crisis has passed, but keep the statement page accessible. It is part of the institutional record and demonstrates transparency to future funders or regulators.
This is a governance risk that should be addressed before a crisis occurs. If routine updates require developer access, the organisation cannot respond to a public crisis within the necessary timeframe. The CMS should allow authorised staff to publish content independently.
Include crisis provisions in your website governance policy: who can authorise changes, how quickly updates must be made, what the escalation path is if the Communications Director is unavailable, and who makes decisions if the Executive Director is the subject of the crisis. Test that your team can publish urgent content independently.